Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Freeciv

First CVE: Mar 7, 2006Active for: 20 yearsTotal CVEs: 6

Freeciv is a free, open-source implementation of the Civilization strategy game that supports multiplayer play through networked servers, creating an attack surface around game-state synchronization and network command handling. Its vulnerability profile centers on a single product and clusters around resource-handling and input-validation weaknesses—including buffer overflows, uncontrolled resource consumption, OS command injection, and improper input validation—that are characteristic of network protocol parsers in game engines; these disclosures have a strong tendency toward public exploit availability. Defenders and server operators should treat Freeciv instances as potential pivoting points if exposed to untrusted networks, particularly those hosting multiplayer servers; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Freeciv over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 7, 2006
20 years ago
Most Recent CVE
Aug 31, 2022
1,423 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-6083HIGH
Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet.
Jan 23, 20207.540NOYES
CVE-2010-2445HIGH
freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the
Jul 8, 201010.029NONO
CVE-2022-39047HIGH
Freeciv before 2.6.7 and before 3.0.3 is prone to a buffer overflow vulnerability in the Modpack Installer utility's handling of the modpack URL.
Aug 31, 20228.828NONO
CVE-2012-5645HIGH
A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that,
Dec 30, 20197.526NONO
CVE-2006-0047MEDIUM
packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values.
Mar 7, 20065.025NOYES
CVE-2006-3913HIGH
Buffer overflow in Freeciv 2.1.0-beta1 and earlier, and SVN 15 Jul 2006 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary cod
Jul 28, 20067.521NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
17%
83%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (50.0%)
Unknown3 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (50.0%)
High0 (0.0%)
Unknown3 (50.0%)
User Interaction
None2 (33.3%)
Unknown3 (50.0%)
Required1 (16.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (50.0%)
Unknown3 (50.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
33.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Freeciv.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Freeciv — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Freeciv's Products

View all 3 CNAs →

Top CWEs